Learn about CVE-2020-28391 affecting Siemens SCALANCE X-200, X-200IRT, and X-200RNA switch families. Discover the impact, affected versions, and mitigation steps.
A vulnerability has been identified in SCALANCE X-200 switch family, SCALANCE X-200IRT switch family, and SCALANCE X-200RNA switch family.
Understanding CVE-2020-28391
This CVE involves a cryptographic key vulnerability that could lead to a man-in-the-middle attack.
What is CVE-2020-28391?
The vulnerability allows attackers to decrypt previously captured traffic due to the devices using a hardcoded private RSA key when used with C-PLUG.
The Impact of CVE-2020-28391
Exploiting this vulnerability could result in unauthorized access to sensitive information and compromise the integrity of communication.
Technical Details of CVE-2020-28391
The following technical details outline the specifics of this CVE.
Vulnerability Description
Devices in the SCALANCE X-200 switch family, SCALANCE X-200IRT switch family, and SCALANCE X-200RNA switch family create a new unique key upon factory reset, except when used with C-PLUG, where a hardcoded private RSA key is utilized.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability to conduct man-in-the-middle attacks and decrypt previously captured traffic.
Mitigation and Prevention
Protecting systems from CVE-2020-28391 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates